Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

481–490 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#481

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

I’ve noticed a lot of things that start going wonky with Lockdown mode on.

Continuity seems to go right out the window for me for one, which is something I really rely on.

Airplay also seems to become really temperamental.

All of this could just be my network but it only seems to have been the case since switching to lockdown mode.

Also, screen time requests don’t work which is a real pain.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#482

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

Capitalist view: If they didn't emphasize it, some first-time Apple customers might be convinced by concerned friends and family to enable Lockdown Mode by default, and then might complain to Apple / return their device because it "doesn't do the things it was advertised to do" (because those features don't work in Lockdown Mode.)

Realpolitik view: repressive regimes probably only allow Apple to release devices with this feature available, as long as they don't heavily push it / make it the default. If Lockdown Mode defaulted to "on" in China, and so was used by the majority of users, then Apple would be quickly booted out of China.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#483
post #369
post #361

Earlier quoted context omitted.

It's also insecure. The sync keys for iMessage are backed up in the non-e2ee iCloud Backup, which means that iCloud serves as a key escrow for iMessage's e2ee, rendering it useless (as Apple, which is definitively not an endpoint, has a private key of the participant and can read all the messages in real-time). iMessage should be assiduously avoided.

This is less true now, with the option to enable “advanced data protection”. Turning this setting on disables Apple’s access to your iMessage keys along with a bunch of other stuff, though of course if you get locked out, Apple can’t help you

I don’t believe this is true. You can change your iCloud password at any time, which means they definitely are not encrypting your iCloud data based on that key or a derivative. If I had to guess, they generate a key and encrypt that key with your password so it can be changed but they also aren’t able to produce it on request.

The drawback here is that the encryption key for your data never changes, even if you change your password (the private key is just re-encrypted with the new password).

If they’ve implemented it well then this is mostly academic but it does mean they must be escrowing encrypted keys for every account, and those with ADP enabled are just encrypted against their password rather than the Apple key. It also means if they’ve suffered an undetected breach in the past then changing your password doesn’t help protect your data going forward necessarily. That being said, if an attacker had ongoing access to iCloud data then it probably doesn’t matter (although the presumably-more-secure key vault wouldn’t need to be breached again).

I have no insight into Apple’s practices and this is all speculation, this is just the trade-off I would make to keep it usable.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#484
post #468

There needs to be a more fine tuned lockdown mode, for example to disable automations and risks in imessage and safari but leave device accessories working. Losing bluetooth accessories to protect yourself from zero click imessage exploits is just bad. imessage is the major wide open attack surface.

Settings already allows you to "tune your lockdown mode" to suit your preferences.

For example Settings > Messages > iMessage is literally a switch to turn off iMessage if you feel that it's problematic.

Settings > Safari > Privacy and security has various settings which allow you to have a 'more fine tuned lockdown' for safari.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#485
post #46

Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough. These scumbags belong in the Hague(metaphorically at least).

>Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough Somewhere in a nondescript subterranean hangar north of vegas an unacknowledged aerial platform is getting an itchy nose

Given where the group is headquartered, I doubt it. That unacknowledged aerial platform will remain firmly planted on the ground until the next defenseless target is chosen.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#486
post #482

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

Capitalist view: If they didn't emphasize it, some first-time Apple customers might be convinced by concerned friends and family to enable Lockdown Mode by default, and then might complain to Apple / return their device because it "doesn't do the things it was advertised to do" (because those features don't work in Lockdown Mode.) Realpolitik view: repressive regimes probably only allow Apple to release devices with…

Yes, this is the angle I've been trying to capture. Its realpolitik, thank you for helping crystalize that. But I maintain that it extends to the US as well in terms of cooperation with domestic enforcement bodies.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#487

How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.

This is very different from ActiveX. ActiveX had hundreds of exploits widely available freely on the dark parts of usenet, and exploited by every proverbial scriptkiddie in a basement against a swath of computers across the world.

iMessage has had a handful of exploits which are licensed out for extortionate amounts by people like NSO to a very small number of scummy nationstate threat actors in extremely targetted but very high-threat attacks on very high-profile targets.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#488
post #46

Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough. These scumbags belong in the Hague(metaphorically at least).

>Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough Somewhere in a nondescript subterranean hangar north of vegas an unacknowledged aerial platform is getting an itchy nose

I hear NSO group keeps several million barrels of oil on them at all times, and also definitely WMDs.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#489

Earlier quoted context omitted.

If there is anything that is life critical for a large number of people then it is their phones.

I think pacemakers are a lot more life critical than your phone. I broke my phone once. I did not die in the next five minutes

Pacemakers are one of literally millions of regulated medical devices. If my CPAP fails one night, I don't die, but it's still regulated to ensure it's not gonna fail. You want this to be pacemakers vs Tetris but it's not. It's hearing aids and contact lenses and insulin pumps and wheelchairs and nebulizers and all kinds of devices that will not get you killed if they fail AND YET they are highly regulated and rightly so.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#490

Earlier quoted context omitted.

The US government gives them billions of dollars and they help the US government maintain puppet dictatorships like Saudi Arabia..

And the US barely has an inherent interest in Saudi Arabia. Israel is credited for helping the US "fight terrorism in the Middle East" or maintain those puppets, but really they're just helping us help them. When it comes to things that don't directly benefit Israel, they don't care. Israel has never even fought ISIS for example, the largest recent terrorist threat in the region. And they're allowed to maintain some…

It’s truly shocking how misinformed you are about foreign policy.

Israel attempted to maintain some level of neutrality wrt Russia bec when they show preferences, Russia punishes the local Jewish population… which they promptly did as soon as Israel showed any support for Ukraine.

Israel shares a ton of intel with the US regarding many of the local terrorist organizations in the ME. Not to mention they’re flying sorties into Syrian airspace almost nightly. (Infamously Syria AA shot down a russian spy plane, killing 11, thinking they finally caught an Israeli plane)

And Israel’s absence from that symbolic list was likely a precondition to get many of those Arab and African nations on the list. Israel has ISIS locally so there’s no doubt they’re fighting isis.

Finally wrt the Jordan’s west bank: they lost it years ago and it’s so odd you keep calling it that… maybe use the actual name for the area and suddenly Israel’s policy will make sense.

Post reply on HN